Qakbot Malware: Exploring Its Diverse Distribution Methods
ID: 3efa7160-2bec-55da-93b1-6fad306d0cbc
STIX ID: report--3efa7160-2bec-55da-93b1-6fad306d0cbc
Feed Name: Cyble Blog
Threat Score
This report analyzes active Qakbot campaigns that deliver a modular banking trojan via malspam using OneNote attachments and archived script files (.wsf, .jse, .hta), describing multi-stage chains (BAT/PowerShell/WScript/msthta → DLL payload executed with rundll32), process injection and credential-theft capabilities, and providing IoCs (file hashes and download URLs), MITRE ATT&CK mappings, process diagrams, and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
